Beveiligingsadvies

CVE-2020-25843

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-12-31 07:45:46
Laatst bijgewerkt 2024-09-16 18:28:28
Toegewezen door twcert
CVSS-score 8.1
Status PUBLISHED

Beschrijving

NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege.